How to use this reference
Editorial guidance: document which component owns each capability decision and distinguish intended delegation from effective restrictions. Keep browser-feature controls separate from application authorization and user consent in integration reviews.
Before reading
- Browser origins, embedded documents and HTTP response headers
Context and limits
- Work in progress, not a final Recommendation or deployed-compatibility guarantee. Listed authors are the draft's editors.
- User agents need not support every feature. Frame-level observable policy omits child response policy and later navigation, so it does not establish the loaded document's effective access.
- Complements iframe sandboxing; it is not a complete isolation model.
Sources and provenance
- Permissions Policy World Wide Web Consortium · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.